Netstat correcto?? Sospecha de spyware

Responder
alucina
Mensajes: 1
Registrado: 05 Feb 2010, 13:31

Netstat correcto?? Sospecha de spyware

Mensaje por alucina » 05 Feb 2010, 13:56

Hola!



Para empezar quisiera daros las gracias a todos los que participáis en el foro. Mi portátil hacía cosas muy raras (desconexión espontánea de internet pese a que la línea funciona perfectamente, nueva página de inicio en firefox...) y mirando en esta página me enteré de la posibilidad de pasar el elistara.

Lo he hecho y parece que la cosa va bien, pero sigo teniendo muchas entradas en el netstat que no comprendo. Podríais ayudarme a descifrarlas? Muchísimas gracias! (Las copio a continuación y debajo podéis ver lo que pone en mi archivo InfoSat):



++++++++++++++++++++++++++

Conexiones activas



Proto Dirección local Dirección remota Estado

TCP lucia:2781 localhost:2782 ESTABLISHED

TCP lucia:2782 localhost:2781 ESTABLISHED

TCP lucia:2786 localhost:2787 ESTABLISHED

TCP lucia:2787 localhost:2786 ESTABLISHED

TCP lucia:2784 ey-in-f118.1e100.net:http ESTABLISHED

TCP lucia:2785 62.208.24.34:http ESTABLISHED

TCP lucia:2788 62.208.24.34:http ESTABLISHED

TCP lucia:2789 62.208.24.34:http ESTABLISHED

TCP lucia:2790 62.208.24.34:http ESTABLISHED

TCP lucia:2791 62.208.24.34:http ESTABLISHED

TCP lucia:2792 62.208.24.34:http ESTABLISHED

TCP lucia:2803 ftp.newaol.com:http ESTABLISHED

TCP lucia:2806 136.201.169.194.prisacom.com:http TIME_WAIT

TCP lucia:2813 ww-in-f149.1e100.net:http ESTABLISHED

TCP lucia:2814 62.208.24.75:http ESTABLISHED

TCP lucia:2819 static-ip-85-25-83-36.inaddr.plusserver.de:http

TIME_WAIT

TCP lucia:2820 62.208.24.155:http ESTABLISHED

TCP lucia:2825 ww-in-f149.1e100.net:http ESTABLISHED

TCP lucia:2829 252.201.169.194.prisacom.com:http TIME_WAIT

TCP lucia:2830 62.208.24.81:http ESTABLISHED

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++



(5-2-2010 11:35:41 (GMT))

EliStartPage v20.26 (c)2010 S.G.H. / Satinfo S.L. (Actualizado el 4 de Febrero del 2010)

--------------------------------------------------

Lista de Acciones (por Acción Directa):

Linea Eliminada del HOSTS --> 127.0.0.1 bin.errorprotector.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 br.errorsafe.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 br.winantivirus.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 br.winfixer.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 cdn.drivecleaner.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 cdn.errorsafe.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 cdn.winsoftware.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 de.errorsafe.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 de.winantivirus.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 download.cdn.drivecleaner.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 download.cdn.errorsafe.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 download.cdn.winsoftware.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 download.errorsafe.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 download.systemdoctor.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 download.winantispyware.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 download.windrivecleaner.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 download.winfixer.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 drivecleaner.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 dynamique.drivecleaner.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 errorprotector.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 errorsafe.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 es.winantivirus.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 fr.winantivirus.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 fr.winfixer.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 go.drivecleaner.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 go.errorsafe.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 go.winantispyware.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 go.winantivirus.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 hk.winantivirus.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 instlog.errorsafe.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 instlog.winantivirus.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 instlog.winfixer.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 jsp.drivecleaner.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 kb.errorsafe.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 kb.winantivirus.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 nl.errorsafe.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 se.errorsafe.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 secure.drivecleaner.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 secure.errorsafe.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 secure.winantispam.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 secure.winantispy.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 secure.winantivirus.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 support.winantivirus.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 trial.updates.winsoftware.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 ulog.winantivirus.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 utils.errorsafe.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 utils.winantivirus.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 utils.winfixer.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 winantispyware.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 winantivirus.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 winfixer.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 winfixer2006.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 winsoftware.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 www.drivecleaner.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 www.errorprotector.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 www.errorsafe.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 www.systemdoctor.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 www.utils.winfixer.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 www.win-anti-virus-pro.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 www.win-virus-pro.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 www.winantispam.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 www.winantispy.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 www.winantispyware.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 www.winantivirus.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 www.winantiviruspro.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 www.windrivecleaner.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 www.windrivesafe.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 www.winfixer.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 www.winfixer2006.com ## added by CiD

Linea Eliminada del HOSTS --> 127.0.0.1 www.winsoftware.com ## added by CiD

No detectado SP3 de Windows XP

Eliminadas las Paginas de Inicio y de Busqueda del IE

Eliminados Ficheros Temporales del IE



(5-2-2010 11:39:30 (GMT))

EliStartPage v20.26 (c)2010 S.G.H. / Satinfo S.L. (Actualizado el 4 de Febrero del 2010)

--------------------------------------------------

Lista de Acciones (por Exploración):

Explorando "C:\"

C:\Archivos de programa\BS_Player\TBBS_1.DLL --> Eliminado, TBConduit(tb)

C:\Archivos de programa\BS_Player\TBBS_P.DLL --> Eliminado, TBConduit(tb)

C:\Archivos de programa\eMule\Incoming\OCR ABBYY FineReader V 8.0 Professional Edition ITA-ENG-FRE-POR-SPA by Darkhiei\ABBYY FineReader 8.0 Professional Edition [ITA]-[ENG]-[FRE]-[POR]-[SPA] by Darkhiei\FR80PE_TB_EFSIP.EXE --> Eliminado, LowZones(dr)



Nº Total de Directorios: 16873

Nº Total de Ficheros: 99495

Nº de Ficheros Analizados: 29595

Nº de Ficheros Infectados: 3

Nº de Ficheros Limpiados: 3



(5-2-2010 11:57:52 (GMT))

EliStartPage v20.26 (c)2010 S.G.H. / Satinfo S.L. (Actualizado el 4 de Febrero del 2010)

--------------------------------------------------

Lista de Acciones (por Exploración):

Explorando "C:\"



Nº Total de Directorios: 17214

Nº Total de Ficheros: 132401

Nº de Ficheros Analizados: 29708

Nº de Ficheros Infectados: 0

Nº de Ficheros Limpiados: 0

Avatar de Usuario
msc hotline sat
Mensajes: 93500
Registrado: 09 Mar 2004, 20:39
Ubicación: BARCELONA (ESPAÑA)
Contactar:

Re: Netstat correcto?? Sospecha de spyware

Mensaje por msc hotline sat » 05 Feb 2010, 18:00

Vemos que se ha detectado CiD. Posteanos log generado por el SPROCES y te pediremos los ficheros que veamos sospechosos de Swizzors, inicialmente generados por el CiD a causa del Messenger Plus


[quote="msc"]
[b]SPROCES.EXE[/b] (herramienta de investigación)

http://www.zonavirus.com/descargas/sproces.asp



Y tras pulsar en SALIR, posteanos el contenido del C:\SPROCLOG.TXT [/quote]

lo analizaremos e informaremos al respecto.



saludos



ms, 5-2-2010

Responder

Volver a “Foro Spyware”